Followed Read & Run Me + XP Cleaning Procedure, need help

Discussion in 'Malware Help (A Specialist Will Reply)' started by 2pro4show, Aug 4, 2008.

  1. 2pro4show

    2pro4show Private E-2

    Let me first explain how I got to this point.

    Another user on this PC was attempting to use QuickTax 2007, but once the program was opened, an "Internet Explorer Script Error" pop-up appeared, with all the lines which were supposed to detail the error blank. This also appeared a few times on startup when a Norton AntiVirus subscription reminder would appear (Norton has since been uninstalled). The only way to get rid of this is to press "X" in the window - the "Yes" and "No" buttons do not function. After pressing 'X", the script error dialog pops up again and again, you have to close roughly 20 instances of it before it finally disappears. When this occurred with QuickTax, it wouldn't disappear at all.

    Now, whether this is malware or not, I'm not sure. I did a bit of searching and from what I can understand it may have something to do with IE and ActiveX controls. At the moment, Internet Explorer does not work properly: as soon as it's opened it hogs up all resources and is unresponsive. I have to end the process via Task Manager to get rid of it.

    In light of this, I decided to uninstall Norton & install Comodo Personal Firewall, Comodo BOClean, Comodo AntiVirus, Spybot Search & Destroy with TeaTimer turned off and Spyware Blaster with full protection (this would give me the same setup as on my other computer, which was previously cleaned of malware thanks to this site). Comodo AntiVirus was the only program which had difficulties. It seemed to install just fine and it would open with no problems, but all the buttons wouldn't function. I couldn't switch tabs/settings, run scans, minimize or close the window - basically all functions had no effect. Yet the program itself wasn't unresponsive: I could minimize/close the program by the taskbar and I could open the right-click menu from the tray icon. I made a thread here about that problem, at which point I was directed to this forum.

    Anyhow, whether any of what I've described is malware or not, I thought it best to come here and go through the Read & Run Me and the XP Cleaning Procedure. I ran into one problem: SUPERAntiSpyware's scan ran for about 45 minutes until it stopped at a point in the scan. I left it for another 2 and a half hours, but nothing had change. I then decided to end the scan by pressing "Next". A dialog popped up and I said "Yes" to ending the scan prematurely. Nothing happened. I waited longer, but still nothing. The cancel and "X" buttons did nothing either. I had to end the process via Task Manager. As a result no log was obtained. Here is a screenshot, just before I ended the process.

    The rest of the scans were fine. Spybot found a bunch of tracking cookies mostly, but it also found instances of "PUPS" (not sure what that is) and 3 Trojans. Here are screenshots of those results: Screen 1 Screen 2. I then pressed "Fix selected problems" and that worked fine.

    For some reason, I'm unable to attach anything to this post (the Manage Attachments button isn't there, I turned off my pop-up/ad blocker and I checked the How To Attach Items To Your Post with no luck). I uploaded the logs elsewhere. Here they are (yellow Download button at the bottom of each page):

    Malwarebytes Anti-Malware log
    ComboFix.txt
    MGlogs.zip

    Finally, just to clarify, my priority right now is to rid this machine of malware. If that involves the "Internet Explorer Script Error" I described, great, otherwise, I'll tackle that problem separately later.

    Thanks.

    [edit by chaslang] Logs attached here for easier and permanent access.
     

    Attached Files:

    Last edited by a moderator: Aug 4, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No your problems are not due to malware so you will have to work them in the Software Forum. However I do have some steps for you to take. They are not directly related to what you are complaining about. They are just left overs like Norton/Symantec not getting removed properly and other junk.

    Run this Norton Removal Tool (SymNRT) and then reboot!!!! Then run it one more time.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines (some may be gone already after running the Norton removal) but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
    O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
    O4 - HKLM\..\Run: [NAV CfgWiz] "C:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT"
    O4 - HKLM\..\Run: [MediaGateway] C:\Program Files\MediaGateway\MediaGateway.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -

    After clicking Fix, exit HJT.


    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Aug 4, 2008
  3. 2pro4show

    2pro4show Private E-2

    I couldn't find the following entries in the HijackThis:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
    O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
    O4 - HKLM\..\Run: [NAV CfgWiz] "C:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT"
    O4 - HKLM\..\Run: [MediaGateway] C:\Program Files\MediaGateway\MediaGateway.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    The other 3 entries you specified were found and fixed.

    I received a success message about adding the information you supplied to the registry.

    Attached is the log from MGtools.

    Thanks.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A service from Norton still did not get removed. Do the below.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Norton LiveConnect Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteNorton LiveConnect Service into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and then reboot when it tells you it needs to.

    Other than the above we are finished. If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  5. 2pro4show

    2pro4show Private E-2

    Ok. I followed all instructions with no problems.

    Thank you, again, for all the help. Much appreciated.

    I have to ask though, are you sure the "Internet Explorer Script Error" isn't due to malware? The more things I do on the computer the more places I find it. It popped up when I ran "services.msc" like you told me to. It happens when QuickTax is loaded as I already stated. If it isn't malware, do you have any idea what it could be/how to get rid of it?

    Thank you again.
     
  6. 2pro4show

    2pro4show Private E-2

    I have something new to report. This happened just now.

    Under a different User Account than the one I used to clean the computer of malware, whenever Microsoft Word or Windows Live Messenger is opened a Windows Installer pops up to install the software... even though it's already installed. Sometimes a "Copying..." dialog box also pops up (the sort of thing that would appear when copying a large file from one directory on a computer to another), apparently copies files and then disappears rapidly. After canceling the Windows Installer, the program loads and seems to run normally. I haven't tried opening either program on the User Account I used to rid the computer of malware yet.

    Have we done anything to cause this? Is it malware? If not, do you know the problem or solution?
     
  7. 2pro4show

    2pro4show Private E-2

    Ok, I think I was a bit hasty in my assumptions. It doesn't look like malware to me. I let the Windows Installer for Windows Live Messenger run and I don't get a pop up for it anymore. On the Microsoft Word 2003 pop up however, it displays this error message: "A required installation file SKU112.CAB could not be found.", at which point it prompts me for my CD to install Word instead (even though Word is already installed - canceling the installation makes Word open and run as usual). Cancelling the install from this step gives me the following: "Error 25090. Office Setup encountered a problem with the Office Source Engine, system error -2147023179. Please open C:\Program Files\Microsoft Office\OFFICE\1033\SETUP.CHM and look for "Office Source Engine" for information on how to resolve this problem."

    The "Internet Explorer Script Error" messages are still appearing however, and Internet Explorer is still unresponsive and unusable.

    My apologies for the triple post. I would've edited this into the last post but was too slow.

    Thank you for all the help. I hope I'm not being too much of an annoyance. ;)
     
    Last edited: Aug 5, 2008
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not malware. I suggest you look at the below and also post in the Software Forum if necessary:

    http://support.microsoft.com/kb/308260
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds